Repository navigation
Commit 6befe19
fix(metadata-protocol): put and delete accept the version a checksum-less sys_metadata row is served as (#21990)
Fixes #21978
Clause-②: no
## What this changes
`SysMetadataRepository`
(`packages/metadata-protocol/src/sys-metadata-repository.ts`) served a
`sys_metadata` row that has no `checksum` as the hash of its stored body
(`rowToItem`), but `put` and `delete` judged the caller's parent against
the raw column (`existing.checksum ?? null`). So a row like that could
never be written or removed through the metadata door. Every
`saveMetaItem` / `deleteMetaItem` answered `409 METADATA_CONFLICT`
("Expected parent hmac-sha256:… but current is null"), whether the
parent was the version the door served or no `If-Match` was sent at all,
because the door takes the parent from the same read. Publish, rollback
and commit revert over such a row hit the same lock, and the
post-promotion drain of a checksum-less draft was refused and silenced
as a benign race.
Per triage's direction (6014717866), with nothing narrowed and no
backfill:
- **One helper**, `servedVersion(ref, row)`: the stored `checksum`, else
`hashSpec(body, type)`. `rowToItem` now reads it, so every read hands
out this one value.
- **One lock**, `lockAccepts(ref, row, parent)`, used by `put` and
`delete`. It accepts the row's stored stamp, which is the old compare
unchanged: a row with a `checksum` is judged exactly as before, and a
`null` parent still matches a checksum-less row. For a checksum-less row
it also accepts the served version.
- **The conflict's head** (`lockHead`) is the served version, so a 409
on such a row names the version a read hands out (before this, `null`).
A checksum-less row whose bytes do not parse keeps `null` there, so a
lock refusal never becomes a parse error.
- The lineage fields (`previous_checksum`, the event's `parentHash`) and
the no-op check keep reading the raw stamp. So the first write over a
checksum-less row, even with an identical body, stamps the row as usual.
Nothing is rewritten at rest, and the header's "no backfill" non-goal
stands, now with one line on how such a row is served.
**File surface:** as dispatched. The producer that wrote such rows (the
datasource admin door) already stamps a checksum since PR #21977, which
is on `main`, so the remaining work is the stored rows, and that lands
in this repository class. Two test files in the same package: the pins,
plus one fixture comment in
`protocol-publish-drafts-package-scope.test.ts` that this change made
false. Changeset: `@objectstack/metadata-protocol` patch.
## Pins (`protocol.served-content-hash.test.ts`, the existing
conflict-test double)
Through the protocol's real `saveMetaItem` / `deleteMetaItem` /
`publishMetaItem`, on a row seeded with no `checksum`:
- (a) saved and deleted with the version its read serves, in the keyed
form a door hands out: the repository's own `get` read, keyed;
- (a) unpinned (last-write-wins) save and delete succeed: the dogfood
shape;
- (b) a stale keyed token and the raw served hash are still refused with
`METADATA_CONFLICT` / `409` on both doors; `actualHead` is the served
token, the row is untouched, and retrying with that `actualHead`
succeeds;
- (c) a `null` parent still succeeds: `storedParentVersion: row.checksum
?? null`, the stored-row migration's in-process spelling;
- (d) after each write the row carries `hashSpec(newBody, 'view')`; an
identical re-save stamps it too;
- publish over a checksum-less active row; the drain removes a
checksum-less draft row;
- repository level: a row WITH a checksum whose stamp differs from its
body's hash refuses the body's hash and `null` (both name the stamp as
head) and accepts its stamp; a checksum-less row accepts `null` and its
served version, and refuses anything else with the served version as
head.
## Reverse verification (committed HEAD `5c4815a6ab`)
The mutation went through `scripts/ablation-replace.mjs` with an
EXIT/INT/TERM restore trap and absolute paths. It restored the raw
compare in both `put` and `delete` (anchor hit x2 → x0, replacement x0 →
x2, blob `dc58518587` → `494fa3f0ee`; on disk, raw-compare 0 → 2 and
`lockAccepts` call 2 → 0).
- Predicted beforehand: 7 of the 9 new pins red, and green for the
`null`-parent pin and the stamped-row pin, which guard against widening
and against narrowing rather than this mutation.
- **Observed: `Tests 7 failed | 16 passed (23)`**, the 7 predicted. The
save door reproduced the card's text verbatim: "view/case_grid has been
modified since you loaded it. Expected parent hmac-sha256:e532d121… but
current is null." The drain pin read the draft row still present, and
the repository pin read `actualHead` `null`.
- Restore was proven by observation: blob after restore `dc58518587`
equals the HEAD blob, `git diff HEAD` is empty, and `git status
--porcelain` is empty.
- An earlier invocation was a no-op: the tool refused with exit 2 before
writing, because it located the repository from the shared checkout's
cwd. On-disk counts were unchanged, and it was rerun from the worktree
root.
The subject is imported by relative `src` path (`./protocol.js`,
`./sys-metadata-repository.js`), so no `dist/` sits on the ablation's
resolution path.
## Clause-② (measured against the built entry declarations)
`packages/metadata-protocol/dist/index.d.ts` was built at HEAD, and
again with BASE `8a399b2b15`'s repository source swapped in behind a
trap. The swap was restored and proven by blob equality, and HEAD was
rebuilt, giving a byte-identical `index.d.ts`. The diff's non-comment
lines are `private servedVersion;`, `private lockHead;` and `private
lockAccepts;`, with 0 removed; everything else is doc text.
`index.d.cts` has the identical diff. No exported type or signature
moves. Behaviourally, `put` / `delete` accept for a checksum-less row
the version the same repository already serves for it, which is the
declared version token, not a new class of input.
## Tests and gates: all on HEAD `81606021e2` (after merging
`origin/main` twice, the second bringing PR #21979's `protocol.ts`
change)
- `pnpm --filter @objectstack/metadata-protocol test`: `Test Files 218
passed | 3 skipped (221)`, `Tests 28028 passed | 19 skipped (28047)`.
`typecheck`: `tsc --noEmit` clean, and the test file is in the program
(`--listFiles` count 1). Lock VERDICT command-exit 0.
- `node scripts/pm/dispatch-gates.mjs --commands` (no paths) derived the
63 commands, and all ran at exit 0. `check:type-check-debt` ran under
the verify lock ("1 ledger entr(ies) re-measured … 26 raw tsc error(s)
total, none above its recorded number"). `check:dual-build-cjs-loads`
and `check:lean-entry-closure` ran after a full `turbo run build` (72
tasks, 71 cached). Reconciliation, `--ran` with per-command exit codes:
"63 derived, 63 run, 0 NOT-MEASURED, 0 UNRUN".
- The artifact-roster block (55 families, outside the total): 52 at exit
0. `check-closing-target-claim`, `check-partof-closing-keyword` and
`check-single-claim-paths` answered NOT WIRED (exit 2, no PR context);
they are rerun against this PR and reported in the `os-dev-report`
comment.
- The four symbol-anchor sweeps (`check:adr-symbol-anchors`,
`check:scripts-symbol-anchors`, `check:spec-docblock-symbol-anchors`,
`check:adr-anchors`): exit 0.
- NOT MEASURED locally, owned by CI: the five path-scheduled CI jobs
(Test Core shards, Temporal Conformance, Dogfood Regression Gate,
Dogfood Verify CLI, Build Core) and the workspace type-check lanes.
`packages/qa/dogfood/test/datasource-meta-door-reaches-admin-door.dogfood.test.ts`
was not run locally.
## Census: writers of `sys_metadata` that can store a row with no
`checksum`
| Writer | Where | `checksum` | Still producing such rows |
|---|---|---|---|
| `SysMetadataRepository.put` (insert / update) |
`metadata-protocol/src/sys-metadata-repository.ts` | always
`hashSpec(body, type)` | no |
| `SysMetadataRepository.delete` | same file | removes the row. Its
tombstone goes to `sys_metadata_history` with `checksum: null` by design
| n/a (history table) |
| datasource admin door `writeDatasourceRow` |
`service-datasource/src/datasource-admin-plugin.ts` | `hashSpec(record,
'datasource')` since PR #21977; none before | no. Its pre-#21977 rows
are the stored population this PR makes writable |
| datasource admin door delete fallback | same file | `update { state:
'inactive' }`, which keeps the column | no |
| `DatabaseLoader` save / create / `registerRollback` |
`metadata/src/loaders/database-loader.ts` | `contentHash` stamp | no |
| protocol orphan adoption (`package_id` rebind) |
`metadata-protocol/src/protocol.ts` | partial update, which keeps the
column | no |
| protocol legacy delete, permission-set overlay discard |
`protocol.ts`, `plugin-security/src/permission-set-overlay-discard.ts` |
delete only | no |
| `env_id` → `project_id` migration |
`metadata/src/migrations/migrate-env-id-to-project-id.ts` | column
rename DDL | no |
| stored-row migration, flow credential move | `protocol.ts`
`migrateStoredMetadata`,
`service-automation/src/flow-credential-migration.ts` | through
`saveMetaItem` → `put` (stamps) | no. Both were refused on such rows
before this PR and succeed now |
| generic data door, MCP data bridge, flow write nodes, hook bodies | —
| refused: `sys_metadata` declares `apiMethods: ['get', 'list']`, plus
the stored-metadata family refusals | no |
A tombstone reads back as a `delete` event with `hash: null`
(`history()` / `rowToEvent`). `getByHash` never matches it, and
`restoreVersion` refuses it with `VERSION_NOT_RESTORABLE`. **No writer
is still live after this change, so no follow-up card.**
## Acceptance notes
-
`packages/cli/src/commands/migrate/meta.stored-flow-resolution.integration.test.ts`
(about `:190`) explains its explicit `parentVersion: null` by saying a
raw-seeded row's derived parent "would 409". After this change it would
not; the `null` it passes stays valid. Comment drift in another package,
left as is. Owner: none.
- The first write over a checksum-less row records `previous_checksum:
null` / `parentHash: null`, the raw stamp. That is deliberate: no
history row carries the served hash, so naming it would be a parent link
to nothing.
- A conflict-audit note on such a row now reads "current is (withheld)"
where it read "current is null", because the head is no longer null.
- `DraftDrainFailure.draftHash` is documented as "the row's `checksum`".
It is the served version, the same value for a stamped row. This is a
doc imprecision predating this PR.
- Rollback (`restoreVersion`) and commit revert over a checksum-less
active row take the served parent and pass the same lock. This was read
in code; only publish is pinned as the representative internal caller.
- No door read serves a version token for a stored row that has no
history; the tokens come from receipts, history events and a 409's
`actualHead`. So for a legacy row, the 409 is the first place a client
sees its token. The stale-version pin covers that retry.
---
_Generated by [Claude
Code](https://claude.ai/code/session_017ErfyP2Rx7XWHJA27QjyUi)_
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent aa09db5 commit 6befe19
4 files changed
Lines changed: 343 additions & 12 deletions
File tree
- .changeset
- packages/metadata-protocol/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
Lines changed: 4 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
621 | 621 | | |
622 | 622 | | |
623 | 623 | | |
624 | | - | |
625 | | - | |
626 | | - | |
627 | | - | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
628 | 628 | | |
629 | 629 | | |
630 | 630 | | |
| |||
Lines changed: 231 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
33 | 38 | | |
34 | 39 | | |
35 | 40 | | |
| |||
38 | 43 | | |
39 | 44 | | |
40 | 45 | | |
| 46 | + | |
41 | 47 | | |
42 | 48 | | |
43 | 49 | | |
| 50 | + | |
44 | 51 | | |
45 | 52 | | |
46 | 53 | | |
| |||
462 | 469 | | |
463 | 470 | | |
464 | 471 | | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
| 666 | + | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
| 678 | + | |
| 679 | + | |
| 680 | + | |
| 681 | + | |
| 682 | + | |
| 683 | + | |
| 684 | + | |
| 685 | + | |
| 686 | + | |
| 687 | + | |
| 688 | + | |
| 689 | + | |
| 690 | + | |
| 691 | + | |
| 692 | + | |
| 693 | + | |
| 694 | + | |
| 695 | + | |
0 commit comments